


Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Build structure-aware black-box HTTP fuzzers in Rust with composable mutators, schedulers, observers, deciders, and processors for custom web and API…


This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

Minimal Python proof-of-concept for CVE-2026-64638 that sends a crafted HTML/JSONP XSS payload to WordPress wp-login.php.

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

Exploits CVE-2026-64638 to convert cross-site scripting into shell access on vulnerable web applications, automating payload delivery and…

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Automated HTTP Request Repeating With Burp Suite

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.


This extension enhances Burp Suite by adding several UI and functional features, making it more user-friendly.

Jenkins Git Client RCE CVE-2019-10392_Exp
